InfoSec Handlers Diary Blog

From the Newsdesk of "Stories that won't die", there's some new information regarding the now infamous DigiNotar Certificates. Apparently Microsoft's latest update didn't kill all of the certificates, and I quote from http://support.microsoft.com/kb/2616676/us :

We are investigating an issue with update 2616676 for all Windows XP-based and Windows Server 2003-based systems.
The versions of update 2616676 for Windows XP and for Windows Server 2003 contain only the latest six digital certificates that are cross-signed by GTE and Entrust. These versions of the update do not contain the digital certificates that were included in update 2607712.